CVE-2025-7222 (CNNVD-202507-2712)
中文标题:
Luxion KeyShot 缓冲区错误漏洞
英文标题:
Luxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
漏洞描述
中文描述:
Luxion KeyShot是美国Luxion公司的一款用于设计三维场景照片的软件。该软件可实时3D渲染工作流程可立即显示结果,并缩短创建逼真产品照片所需的时间。 Luxion KeyShot存在缓冲区错误漏洞,该漏洞源于解析3DM文件时存在越界写入,可能导致远程代码执行。
英文描述:
Luxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26473.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Luxion | KeyShot | 13.2.1 | - | - |
cpe:2.3:a:luxion:keyshot:13.2.1:*:*:*:*:*:*:*
|
| luxion | keyshot | 13.2.1 | - | - |
cpe:2.3:a:luxion:keyshot:13.2.1:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-7222 |
2025-11-11 15:23:35 | 2025-11-11 07:40:51 |
| NVD | nvd_CVE-2025-7222 |
2025-11-11 15:00:57 | 2025-11-11 07:48:37 |
| CNNVD | cnnvd_CNNVD-202507-2712 |
2025-11-11 15:12:51 | 2025-11-11 08:00:01 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-202507-2712
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']